Imports users and role grants, the CMDB (computers, network devices, business applications and services, and their dependencies) and ITSM tickets (incidents, changes, catalog requests, SLAs) from your ServiceNow instance through the Table API — plus the Security Incident Response, Vulnerability Response, HR Service Delivery and Software Asset Management modules if you own them.
For the general flow of adding a source, see Connect Data Sources.
Before you start
A ServiceNow instance on the Washington DC release (Q1 2024) or later — the first release that supports the OAuth client credentials grant
A ServiceNow administrator account that can elevate to security_admin to create ACLs
💡 HARVEN authenticates with OAuth 2.0 client credentials mapped to a dedicated integration user. The instance acts as that user for every request, so its roles define exactly what HARVEN can read.
Step 1 — Create the integration user
Open User Administration → Users → New and create a dedicated user, e.g. harven.integration
Tick Web service access only
Grant snc_platform_rest_api_access, required to reach the Table API
Grant read access to the tables HARVEN reads: sys_user, sys_user_role, sys_user_has_role, sys_user_group, sys_user_grmember, cmdb_ci_computer, cmdb_ci_netgear, cmdb_ci_business_app, cmdb_ci_service, cmdb_rel_ci, incident, change_request, sc_req_item, sc_item_option_mtom and task_sla — for example itil for the ITSM tables and a CMDB read role
Optional: add snc_read_only so the instance refuses any write from this user. If token requests then fail, exempt the oauth_credential table
⚠️ Never grant admin or security_admin to the integration user: it would lose its read-only guarantee.
Step 2 — Make protected roles visible
ServiceNow filters every read through ACLs evaluated against the reader's roles, and hides sensitive roles (admin, security_admin…) from non-admin users. Without this step, those roles are missing from the roles table, their grants show an empty role_name, and a question like "who is a ServiceNow administrator?" answers 0 while administrators exist.
Sign in as an administrator, then elevate: user menu → Elevate role → tick security_admin
Create a dedicated role, e.g. u_harven_reader (User Administration → Roles → New), and grant it to the integration user
Open System Security → Access Control (ACL) → New and create two ACLs of type record, operation read, both requiring u_harven_reader: one on sys_user_role (field -- None --) for the role rows, one on sys_user_role.* for their fields, including name
Check it: Impersonate user → the integration user → open sys_user_role.list. If admin is listed, the setup is correct
💡 If admin stays hidden, look for a Deny-Unless ACL on sys_user_role: it overrides an allowing ACL. While roles stay hidden, HARVEN says so in its results and never concludes that there are no administrators.
Step 3 — Enable the client credentials grant
Switch the application scope to Global
Open sys_properties.list and set glide.oauth.inbound.client.credential.grant_type.enabled to true — create the property if it does not exist
Step 4 — Register the OAuth application
Open System OAuth → Application Registry → New → Create an OAuth API endpoint for external clients
Name it HARVEN
The OAuth Application User field is hidden by default: add it through Configure → Form Layout, then set it to the integration user from Step 1
Save, then copy the Client ID and the Client Secret
Step 5 — Check the rate limit rules
Every table is read live on each query. Under System Web Services → REST → Rate Limit Rules, exempt the integration user or raise its hourly limit — otherwise large queries are throttled (HTTP 429).
Step 6 — Licensed modules (optional)
Four tables exist only when the matching ServiceNow product is installed. Grant the integration user read access to those you own:
sn_si_incident — Security Incident Response
sn_vul_vulnerable_item — Vulnerability Response
sn_hr_core_case — HR Service Delivery
cmdb_sam_sw_install — Software Asset Management
For modules you don't own, reads fail with an explicit message ("… needs the X module") without affecting the rest of the connector.
Step 7 — Configure the connector in HARVEN
Open Workspace → Data sources → Add → ServiceNow
Enter the instance URL, the Client ID and the Client secret
Test the connection before saving: the test gets a token, then reads one user — it checks both the OAuth credentials and the read access
What to enter in HARVEN
Instance URL — Your instance address, from the browser address bar (e.g. acme.service-now.com). Only *.service-now.com and *.servicenowservices.com are accepted
Client ID — OAuth application client ID (System OAuth → Application Registry)
Client secret — OAuth application client secret (System OAuth → Application Registry)
What HARVEN reads
servicenow_users — Platform user accounts: identity and join keys (user_name, email, employee_number), lifecycle (active, locked_out, last_login_time, failed_attempts), service accounts (web_service_access_only, internal_integration_user), local-login MFA (enable_multifactor_authn — ServiceNow's own login only, not an org-wide MFA figure)
servicenow_roles — Role catalog: role (name, description, elevated_privilege, includes_roles)
servicenow_user_roles — Role grants, direct and inherited: grant (user_name, role_name, granted_by, inherited)
servicenow_groups — User groups: identity (name, type, active), ownership (manager, parent)
servicenow_group_members — Group membership: membership (user_id, group_id)
servicenow_cmdb_computers — CMDB computers and servers: identification and join keys (name, fqdn, serial_number, ip_address), posture (os, os_version, operational_status, install_status), ownership (assigned_to, managed_by, support_group), freshness (last_discovered, discovery_source)
servicenow_network_devices — CMDB network equipment: identification (name, ip_address, serial_number, device_type), firmware (manufacturer, model_id, firmware_version), freshness (last_discovered)
servicenow_business_apps — Application inventory: application (name, application_type, platform, vendor), criticality (business_criticality, user_base), lifecycle (life_cycle_stage, operational_status), ownership (owned_by, it_application_owner)
servicenow_business_services — Business services: service (name, service_classification, used_for), criticality (business_criticality, operational_status), ownership (owned_by, support_group)
servicenow_ci_relationships — CMDB dependencies between services, applications and machines: relationship (parent_name, parent_class, child_name, child_class, type_name)
servicenow_incidents — IT service desk tickets: classification (category, subcategory, priority, severity), handling (state, assignment_group, close_code, reopen_count), latency and MTTR (opened_at, resolved_at, closed_at), scope (cmdb_ci)
servicenow_change_requests — Change records: classification (type, category, risk, short_description), approval and outcome (approval, state, close_code), implementation window (start_date, end_date, work_start, work_end)
servicenow_requested_items — Service catalog requests, including offboarding and access removal: request (cat_item_name, requested_for_user_name, stage, approval), handling (state, assignment_group), latency (opened_at, due_date, closed_at)
servicenow_request_variables — Answers to catalog form questions, per requested item: answer (request_item_number, variable_label, value)
servicenow_task_slas — Response and resolution SLAs per ticket: SLA (task_number, task_table, sla_name, stage), breach (has_breached, business_percentage, planned_end_time, end_time)
servicenow_security_incidents — Security Incident Response cases (requires the SIR module): classification (category, subcategory, priority, risk_score), handling (state, substate, assignment_group), latency (opened_at, closed_at)
servicenow_vulnerable_items — Vulnerabilities per machine (requires Vulnerability Response): vulnerability (vulnerability_id, vulnerability_summary, risk_rating, risk_score), asset (cmdb_ci_name), exposure (state, first_found, last_found, closed_at)
servicenow_hr_cases — HR Service Delivery cases, including offboarding (requires HRSD): case (hr_service_name, subject_person_user_name, state), latency (opened_at, due_date, closed_at)
servicenow_software_installs — Installed software per machine (requires Software Asset Management): install (installed_on_name, display_name, publisher, version), freshness (install_date, last_scanned)
Official documentation
Need help? Contact [email protected].